Data Processing Addendum
This Data Processing Addendum (“DPA”) describes how Wynlo Technologies LLC (“Wynlo”) processes Customer Content on behalf of a customer — typically an insurance agency or other business (“Customer”) — under the Terms of Service. It supplements the Terms for customers whose use of Wynlo is subject to data-protection or financial-privacy obligations, and forms part of the agreement between Wynlo and such a Customer.
1. Parties and roles
The Customer determines what information its business enters into Wynlo and why — including lead, client, call, and pre-application records. For that information, the Customer acts as the controller (or “business”), and Wynlo acts as a service provider/processor: Wynlo processes Customer Content to provide the Service to the Customer, on the Customer’s behalf. For Wynlo’s own account, billing, and operational records, Wynlo acts for itself as described in the Privacy Policy.
2. Instructions and permitted processing
- Wynlo processes Customer Content only to provide, secure, support, and improve the Service as described in the Terms and the Privacy Policy, as configured by the Customer in the product, and as otherwise instructed in writing where Wynlo agrees the instruction is operationally reasonable.
- Wynlo does not sell Customer Content, does not use it for advertising, and does not permit service providers to use it for their own purposes.
- Aggregated, de-identified operational information may be used to run and improve the Service, as stated in the Terms.
3. Confidentiality
Wynlo limits access to Customer Content to personnel and service providers who need it to operate, support, or secure the Service, and who are bound by confidentiality obligations. Administrative access by Wynlo operators is logged.
4. Security
Wynlo maintains safeguards appropriate to the Service as described in the Privacy Policy’s Security section — including encryption in transit, provider-supplied encryption at rest, row-level access controls scoping records to the owning account, verified sign-up identity, server-side authorization of privileged operations, and audit logging of administrative actions. Wynlo does not claim particular security certifications and does not promise that any system is perfectly secure; this DPA describes the safeguards Wynlo actually operates.
5. Subprocessors
The Customer authorizes Wynlo to use the service providers listed on the Subprocessors page to process Customer Content for the functions described there. Wynlo updates that page when the list changes; the Customer can review it at any time. Wynlo remains responsible to the Customer for its subprocessors’ performance of the functions Wynlo engages them for.
6. Assistance with rights requests
Consumers whose information a Customer entered should ordinarily direct privacy requests to that Customer, which controls those records. Wynlo provides reasonable assistance — through the Service’s existing capabilities and through info@wynlo.io — so the Customer can respond to valid access, correction, and deletion requests. Requests Wynlo receives directly about a Customer’s records are referred to that Customer where appropriate.
7. Incident cooperation
If Wynlo confirms a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Customer Content, Wynlo will notify the affected Customer without undue delay, share the information reasonably available about the nature and scope of the incident as the investigation develops, and cooperate reasonably with the Customer’s own notification obligations. The Customer remains responsible for its own legal notification duties.
8. Deletion and return
The Customer’s records remain available in the Service while the account is open. On verified request following account closure, Wynlo will delete or return Customer Content, subject to legal record-keeping duties (insurance sales records often carry multi-year retention expectations), evidence records the law expects to be preserved, and technical constraints such as delayed deletion from backups. Wynlo is candid that deletion is currently a manual, support-assisted process; the Privacy Policy describes retention honestly and will be updated as practices evolve.
9. Customer responsibilities
- The Customer is responsible for the lawfulness of the information it collects and enters — including the notices, consents, and permissions its own collection and calling require.
- Where Customer Content includes nonpublic personal information subject to financial-privacy or insurance-privacy laws (such as the GLBA or state insurance information regulations), the Customer instructs Wynlo to process it only to deliver the Service, and Wynlo limits its use and disclosure accordingly — consistent with the reuse and redisclosure limits that apply to service providers under those laws.
- The Customer is responsible for administering its own users’ access and for the accuracy of the records its business maintains in Wynlo.
10. Information and cooperation
On reasonable written request, no more than once per year absent a genuine incident or regulatory need, Wynlo will provide information reasonably necessary to demonstrate how Customer Content is processed under this DPA — in the form of written responses and existing documentation. This DPA does not grant on-premises inspection rights, and does not obligate Wynlo to disclose other customers’ information or security details that would weaken the platform.
11. Term and precedence
This DPA applies while the Terms apply to the Customer and for as long as Wynlo processes Customer Content on the Customer’s behalf. If this DPA conflicts with the Terms, the Terms control, except that for the subject matter of data processing this DPA controls. Questions: info@wynlo.io.
Questions about this document? Contact info@wynlo.io.
